Blurred Lines of Cyber Threat Attribution: The Evolving Tactics of North Korean Cyber Threat Actors
2025-08-10 • Zscaler •
Attachments
Seongsu Park’s DEF CON material examines how North Korean cyber operations have evolved from broad umbrella labels into multiple specialized clusters with overlapping tools, infrastructure, and mission sets. The slides describe Lazarus-linked history, Kimsuky expansion, and operational specialization across financial crime, espionage, and intelligence collection, arguing that TTP-based clustering is needed for more accurate attribution. One case highlights PEBBLEDASH activity where Lazarus-linked malware traits appeared alongside Kimsuky-associated C2 infrastructure, including address.linkedin.p-e[.]kr and phishing infrastructure using shortened URLs and naverdomain-themed domains. The material also details post-exploitation behaviors such as PowerShell command execution, HazyLoad proxy use, Ngrok tunneling, RDP account creation, and Chrome Remote Desktop installation, showing why full-chain analysis matters when DPRK groups share or reuse tools.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://buly.kr/uTnE2J | 2025-08-10 | 2026-04-07 |
| URL | https://buly.kr/FLXvf9J | 2025-08-10 | 2026-04-07 |
| URL | http://address.linkedin.p-e.kr/… | 2025-08-10 | 2026-04-07 |
| URL | https://buly.kr/ESy8l3Z | 2025-08-10 | 2026-04-07 |
| DOMAIN | buly.kr | 2025-08-10 | 2026-04-07 |
| DOMAIN | address.linkedin.p-e.kr | 2025-08-10 | 2026-04-07 |
| DOMAIN | secure.naverdomain.r-e.kr | 2025-08-10 | 2026-04-07 |
| URL | http://gsegse.dasfesfgsegsefsed… | 2025-05-19 | 2026-04-07 |
| DOMAIN | gsegse.dasfesfgsegsefsede.o-r.kr | 2025-05-15 | 2026-04-07 |
| URL | http://gtfydu.surfnet.ca/index.… | 2025-04-11 | 2026-04-07 |
| DOMAIN | gtfydu.surfnet.ca | 2025-04-11 | 2026-04-07 |
| HASH | ca93591a9441a2ade70821f67292d982 | 2025-03-04 | 2026-04-07 |
| HASH | 9e94126e8a26efd10b2a5b179d64be90 | 2025-03-04 | 2026-04-07 |